Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add hooks/rbah31/claude-code-workflow/pre-tool-usegit clone --depth 1 https://github.com/rbah31/claude-code-workflowGrade D, and why
PreToolUse scanned grade D with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the commands this hook runs, not an audit. A hook is shell that executes on your machine at the event it names, which is why every command in it is printed with what was found.
Asks for rootmediumPrivilege escalation
A mod that escalates privileges can change anything on the machine, not only the project.
"command": "CMD=$(python3 -c \"import json,sys; print(json.load(sys.stdin).get('tool_input',{}).get('command',''))\" 2>/dev/null); for PATTERN in 'rm -rf /' 'rm -rf ~' 'git push --force' 'git push -f' 'git reset --hard' Recursive force deletehighDestructive command
rm -rf with a variable or a broad path is one typo away from removing the wrong tree.
"command": "CMD=$(python3 -c \"import json,sys; print(json.load(sys.stdin).get('tool_input',{}).get('command',''))\" 2>/dev/null); for PATTERN in 'rm -rf /' 'rm -rf ~' 'git push --force' 'git push -f' 'git reset --hard' What it actually says
{
"PreToolUse": [
{
"matcher": "Write|Edit",
"hooks": [
{
"type": "command",
"command": "FILE=$(python3 -c \"import json,sys; print(json.load(sys.stdin).get('tool_input',{}).get('file_path',''))\" 2>/dev/null); case \"$FILE\" in /etc/*|/usr/*|/var/*|/System/*|$HOME/.ssh/*|$HOME/.aws/*) echo \"BLOCKED: write outside project directory\" && exit 1;; esac; exit 0"
},
{
"type": "command",
"command": "python3 \"$CLAUDE_PROJECT_DIR/.claude/hooks/block_wiki_write.py\""
}
]
},
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "CMD=$(python3 -c \"import json,sys; print(json.load(sys.stdin).get('tool_input',{}).get('command',''))\" 2>/dev/null); for PATTERN in 'rm -rf /' 'rm -rf ~' 'git push --force' 'git push -f' 'git reset --hard' 'chmod 777' 'mkfs' 'dd if=' 'shutdown' 'reboot'; do echo \"$CMD\" | grep -qF \"$PATTERN\" && echo \"BLOCKED: $PATTERN detected\" && exit 1; done; exit 0"
},
{
"type": "command",
"command": "python3 \"$CLAUDE_PROJECT_DIR/.claude/hooks/protect-uncommitted-hook.py\""
}
]
}
]
}What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 30 lines scan D 229cc30db008
PreToolUse is a hook published in the GitHub repository rbah31/claude-code-workflow (5 stars, last pushed 2mo ago), licensed Apache-2.0. Its token cost is not measured: a hook is shell that never enters the context. A static security scan graded it D with 2 findings (asks for root, recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other hooks, from other repositories
SessionStart
Runs when a session starts, executing llm_wiki_session.py via python3 with --harness and --if-enabled. From nvk/llm-wiki.
PostToolUse
Runs after a tool call finishes for Edit and Write tool calls, running bun run lint. From gmickel/flow-next.
SessionStart
Runs when a session starts on startup, resume and clear, executing check-update.sh via bash. From DheerG/swarms.
SessionStart
Runs when a session starts on startup, executing session_check.py via python3. From s0912758806p/agentic-sop-to-work.
PreToolUse
Runs before the agent uses a tool for Bash, Write and Write tool calls, running an inline shell check (3 commands). From Justdvp/claude-code-templates.
PreToolUse
Runs before the agent uses a tool for Write, Edit, Bash, Agent, Task, SendMessage and TaskStop tool calls, running bash (3 commands). From modu-ai/moai-adk.